NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
83986 | CVE-2016-9011 | The wmf_malloc function in api.c in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (application crash) via a crafted wmf file, which triggers a memory allocation failure. | 2 | 4.3 | Medium | 2017-03-29 | 2017-03-27 | View | |
18706 | CVE-2016-2493 | The Broadcom Wi-Fi driver in Android before 2016-06-01 on Nexus 5, Nexus 6, Nexus 6P, Nexus 7 (2013), Nexus Player, and Pixel C devices allows attackers to gain privileges via a crafted application, aka internal bug 26571522. | 2 | 9.3 | High | 2017-01-19 | 2016-06-14 | View | |
18962 | CVE-2016-3087 | Apache Struts 2.3.20.x before 2.3.20.3, 2.3.24.x before 2.3.24.3, and 2.3.28.x before 2.3.28.1, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via vectors related to an ! (exclamation mark) operator to the REST Plugin. | 2 | 7.5 | High | 2017-01-19 | 2016-11-28 | View | |
19218 | CVE-2016-3410 | Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka bugs 103956, 103995, 104475, 104838, and 104839. | 2 | 4.3 | Medium | 2017-02-06 | 2017-02-01 | View | |
19474 | CVE-2016-3705 | The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via a crafted XML document containing a large number of nested entity references. | 2 | 5 | Medium | 2017-01-19 | 2016-12-27 | View |
Page 1103 of 17672, showing 5 records out of 88360 total, starting on record 5511, ending on 5515